Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

3368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——Blubrry PowerpressAI7/10/20267/10/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
AplazadaMedia (6.9)——WordpressAI6/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.
AplazadaAlta (7.2)0.46%—Publishpress CapabilitiesAI6/10/20266/10/2026
Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.
AplazadaCrítica (9.3)0.33%—Sendpress NewslettersAI6/10/20266/10/2026
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
AplazadaMedia (6.5)0.35%—WordpressAI6/10/20266/10/2026
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
AplazadaAlta (7.1)0.18%—Thimpress LearnpressAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
AplazadaAlta (7.2)0.32%—Blubrry PowerpressAI6/10/20266/10/2026
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
AplazadaAlta (8.8)0.36%—Presstigers Simple Event PlannerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
AplazadaMedia (5.1)0.17%—Thimpress LearnpressAI5/10/20266/10/2026
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that…
AplazadaAlta (7.1)0.10%—Blubrry PowerpressAI5/10/20266/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
AplazadaMedia (5.3)0.23%—Blubrry PowerpressAI5/10/20266/10/2026
Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
AplazadaAlta (7.1)0.15%—Cozmoslabs TranslatepressAI4/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.
AplazadaAlta (7.2)0.24%—SeopressAI3/10/20266/10/2026
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (4.9)0.24%—SeopressAI3/10/20266/10/2026
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.20%—Wpdeveloper EmbedpressAI3/10/20266/10/2026
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (6.1)0.22%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input…
AplazadaMedia (6.1)0.21%—Thimpress LearnpressAI3/10/20266/10/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' parameter in all versions up to, and including, 4.4.7 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.8)0.63%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated…
AplazadaMedia (4.3)0.15%—Thimpress LearnpressAI2/10/20262/10/2026
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
AplazadaMedia (5.4)0.18%—Publishpress SeriesAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3.
AplazadaMedia (5.3)0.20%—Thimpress LearnpressAI2/10/20263/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.
AplazadaMedia (6.1)0.15%—Giveaways AND Contests BY RafflepressAI2/10/20262/10/2026
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary…
AplazadaMedia (5.3)0.20%—Giveaways AND Contests BY RafflepressAI2/10/20262/10/2026
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
AplazadaCrítica (9.3)0.24%—Wordpress File UploadAI1/10/20261/10/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
AplazadaAlta (7.5)0.36%—Thimpress LearnpressAI1/10/20263/10/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint.…
Orbitaley — Vulnerabilidades